zentimo.exe

Zentimo

Crystal Rich, Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Zentimo xStorage Manager’.
Publisher:
Crystal Rich, Ltd  (signed and verified)

Product:
Zentimo

Description:
Zentimo - An External Drive Manager

Version:
1.0.4.989

MD5:
9237144c460fccdf48aa6ee0202a609a

SHA-1:
87676bb4b0447f94c80bc2cdf8824a46c5b2a272

SHA-256:
80b2384c3820bbbe48a47c8d81c17e8f6f6f86663aeda9c5755fd424709c564c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:31:43 AM UTC  (today)

File size:
1.6 MB (1,698,128 bytes)

Product version:
1.0.4.989

Copyright:
Copyright © 2010 by Crystal Rich Ltd

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\zentimo\zentimo.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/23/2009 1:00:00 AM

Valid to:
11/25/2010 12:59:59 PM

Subject:
CN="Crystal Rich, Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Crystal Rich, Ltd", L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
54B3167B86CDCBCEA4DF714F2DB82384

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:rv3iJZQTm1L0o1NvbFlmQPLDFFxjzyimFvcy:TyJoEL0o5lNXFjzyim7

Entry address:
0x1000

Entry point:
68, 01, 10, 79, 00, E8, 01, 00, 00, 00, C3, C3, 95, BA, 52, EF, 7D, E1, 30, 24, 80, 69, A3, 15, EF, A7, AD, 72, F7, 87, 4D, F0, A1, 79, 47, 3C, 8F, 0F, 8A, 8E, 24, 9A, 25, 85, 7B, A3, 84, 82, 7C, C3, F0, 86, E3, 36, F8, 93, 38, 52, 43, F6, BC, 88, 9B, 25, 31, E9, 02, C1, 34, 2C, 8F, CE, 26, 78, 85, FB, 58, AE, AA, E4, 89, B2, 8D, 1C, AA, 4D, 4C, 1A, 6F, 0E, D9, 9E, F0, 72, 00, B0, 91, E2, 6F, E9, 70, 81, DB, AD, CF, 69, F2, A1, 26, 2F, 36, 00, 0A, D0, 7B, 24, 17, 78, 65, 8B, 82, 89, 5C, EA, 9E, AB, 79, DA...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
2.1 MB (2,224,128 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Zentimo xStorage Manager

Command:
C:\Program Files\zentimo\zentimo.exe \startup


Scan zentimo.exe - Powered by Reason Core Security